CSS Selector expressions are not properly encoded, which can lead to XSS (cross-site scripting) vulnerabilities.
This is patched in v1.14.0.
Users can apply encoding manually to their selectors, if they are unable to upgrade.
{ "nvd_published_at": "2025-05-30T19:15:29Z", "cwe_ids": [ "CWE-79" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2025-05-28T16:06:03Z" }